Skip to content

Commit cf8f26f

Browse files
ZilongXsipopo
authored andcommitted
[CVE] Bump loader-utils to 2.0.3 to fix CVE-2022-37601 (opensearch-project#2689)
* [CVE] Bump loader-utils to 2.0.3 to fix CVE-2022-37601 Signed-off-by: Zilong Xia <[email protected]> * Update CHANGELOG.md Signed-off-by: Zilong Xia <[email protected]> Signed-off-by: Sergey V. Osipov <[email protected]>
1 parent 904701f commit cf8f26f

File tree

5 files changed

+31
-46
lines changed

5 files changed

+31
-46
lines changed

CHANGELOG.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -80,6 +80,7 @@ Inspired from [Keep a Changelog](https://keepachangelog.com/en/1.0.0/)
8080
- Bumps percy-agent to use non-beta version ([#2415](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/2415))
8181
- Resolve sub-dependent d3-color version and potential security issue ([#2454](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/2454))
8282
- [CVE-2022-3517] Bumps minimatch from 3.0.4 to 3.0.5 and [IBM X-Force ID: 220063] unset-value from 1.0.1 to 2.0.1 ([#2640](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/2640))
83+
- [CVE-2022-37601] Bump loader-utils to 2.0.3 ([#2689](https://github.com/opensearch-project/OpenSearch-Dashboards/pull/2689))
8384

8485
### 📈 Features/Enhancements
8586

package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -87,6 +87,7 @@
8787
"**/hoist-non-react-statics": "^3.3.2",
8888
"**/json-schema": "^0.4.0",
8989
"**/kind-of": ">=6.0.3",
90+
"**/loader-utils": "^2.0.3",
9091
"**/node-jose": "^2.1.0",
9192
"**/nth-check": "^2.0.1",
9293
"**/qs": "^6.10.3",

packages/osd-optimizer/package.json

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -18,38 +18,27 @@
1818
"@osd/std": "1.0.0",
1919
"@osd/ui-shared-deps": "1.0.0",
2020
"autoprefixer": "^10.4.1",
21-
"babel-loader": "^8.2.3",
2221
"clean-webpack-plugin": "^3.0.0",
2322
"compression-webpack-plugin": "^4.0.0",
2423
"cpy": "^8.0.0",
2524
"core-js": "^3.6.5",
26-
"css-loader": "^5.2.7",
2725
"dedent": "^0.7.0",
2826
"del": "^5.1.0",
2927
"execa": "^4.0.2",
3028
"fibers": "^5.0.3",
31-
"file-loader": "^4.2.0",
3229
"jest-diff": "^27.5.1",
3330
"js-yaml": "^3.14.0",
3431
"json-stable-stringify": "^1.0.1",
3532
"lmdb-store": "^1.6.11",
36-
"loader-utils": "^1.2.3",
3733
"normalize-path": "^3.0.0",
3834
"pirates": "^4.0.1",
3935
"postcss": "^8.4.5",
40-
"postcss-loader": "^4.2.0",
41-
"raw-loader": "^4.0.2",
4236
"rxjs": "^6.5.5",
4337
"sass": "~1.26.11",
44-
"sass-loader": "^10.2.0",
4538
"source-map-support": "^0.5.19",
46-
"style-loader": "^1.1.3",
4739
"terser-webpack-plugin": "^2.1.2",
4840
"tinymath": "1.2.1",
49-
"url-loader": "^2.2.0",
50-
"val-loader": "^1.1.1",
5141
"watchpack": "^2.1.1",
52-
"webpack": "^4.41.5",
5342
"webpack-merge": "^4.2.2"
5443
},
5544
"devDependencies": {
@@ -58,6 +47,17 @@
5847
"@types/loader-utils": "^1.1.3",
5948
"@types/source-map-support": "^0.5.3",
6049
"@types/watchpack": "^1.1.6",
61-
"@types/webpack": "^4.41.31"
50+
"@types/webpack": "^4.41.31",
51+
"babel-loader": "^8.2.3",
52+
"css-loader": "^5.2.7",
53+
"file-loader": "^6.2.0",
54+
"loader-utils": "^1.2.3",
55+
"postcss-loader": "^4.2.0",
56+
"raw-loader": "^4.0.2",
57+
"sass-loader": "^10.2.0",
58+
"style-loader": "^1.1.3",
59+
"url-loader": "^2.2.0",
60+
"val-loader": "^2.1.2",
61+
"webpack": "^4.41.5"
6262
}
6363
}

packages/osd-ui-shared-deps/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@
4444
"css-loader": "^5.2.7",
4545
"del": "^5.1.0",
4646
"loader-utils": "^1.2.3",
47-
"val-loader": "^1.1.1",
47+
"val-loader": "^2.1.2",
4848
"webpack": "^4.41.5"
4949
}
5050
}

yarn.lock

Lines changed: 16 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -8650,13 +8650,13 @@ file-entry-cache@^6.0.1:
86508650
dependencies:
86518651
flat-cache "^3.0.4"
86528652

8653-
file-loader@^4.2.0:
8654-
version "4.3.0"
8655-
resolved "https://registry.yarnpkg.com/file-loader/-/file-loader-4.3.0.tgz#780f040f729b3d18019f20605f723e844b8a58af"
8656-
integrity sha512-aKrYPYjF1yG3oX0kWRrqrSMfgftm7oJW5M+m4owoldH5C51C0RkIwB++JbRvEW3IU6/ZG5n8UvEcdgwOt2UOWA==
8653+
file-loader@^6.2.0:
8654+
version "6.2.0"
8655+
resolved "https://registry.yarnpkg.com/file-loader/-/file-loader-6.2.0.tgz#baef7cf8e1840df325e4390b4484879480eebe4d"
8656+
integrity sha512-qo3glqyTa61Ytg4u73GultjHGjdRyig3tG6lPtyX/jOEJvHif9uB0/OCI2Kif6ctF3caQTW2G5gym21oAsI4pw==
86578657
dependencies:
8658-
loader-utils "^1.2.3"
8659-
schema-utils "^2.5.0"
8658+
loader-utils "^2.0.0"
8659+
schema-utils "^3.0.0"
86608660

86618661
file-selector@^0.4.0:
86628662
version "0.4.0"
@@ -12103,19 +12103,10 @@ loader-runner@^2.4.0:
1210312103
resolved "https://registry.yarnpkg.com/loader-runner/-/loader-runner-2.4.0.tgz#ed47066bfe534d7e84c4c7b9998c2a75607d9357"
1210412104
integrity sha512-Jsmr89RcXGIwivFY21FcRrisYZfvLMTWx5kOLc+JTxtpBOG6xML0vzbc6SEQG2FO9/4Fc3wW4LVcB5DmGflaRw==
1210512105

12106-
loader-utils@^1.0.0, loader-utils@^1.2.3:
12107-
version "1.4.0"
12108-
resolved "https://registry.yarnpkg.com/loader-utils/-/loader-utils-1.4.0.tgz#c579b5e34cb34b1a74edc6c1fb36bfa371d5a613"
12109-
integrity sha512-qH0WSMBtn/oHuwjy/NucEgbx5dbxxnxup9s4PVXJUDHZBQY+s0NWA9rJf53RBnQZxfch7euUui7hpoAPvALZdA==
12110-
dependencies:
12111-
big.js "^5.2.2"
12112-
emojis-list "^3.0.0"
12113-
json5 "^1.0.1"
12114-
12115-
loader-utils@^2.0.0:
12116-
version "2.0.2"
12117-
resolved "https://registry.yarnpkg.com/loader-utils/-/loader-utils-2.0.2.tgz#d6e3b4fb81870721ae4e0868ab11dd638368c129"
12118-
integrity sha512-TM57VeHptv569d/GKh6TAYdzKblwDNiumOdkFnejjD0XwTH87K90w3O7AiJRqdQoXygvi1VQTJTLGhJl7WqA7A==
12106+
loader-utils@^1.2.3, loader-utils@^2.0.0, loader-utils@^2.0.3:
12107+
version "2.0.3"
12108+
resolved "https://registry.yarnpkg.com/loader-utils/-/loader-utils-2.0.3.tgz#d4b15b8504c63d1fc3f2ade52d41bc8459d6ede1"
12109+
integrity sha512-THWqIsn8QRnvLl0shHYVBN9syumU8pYWEHPTmkiVGd+7K5eFNVSY6AJhRvgGF70gg1Dz+l/k8WicvFCxdEs60A==
1211912110
dependencies:
1212012111
big.js "^5.2.2"
1212112112
emojis-list "^3.0.0"
@@ -15860,14 +15851,6 @@ scheduler@^0.19.1:
1586015851
loose-envify "^1.1.0"
1586115852
object-assign "^4.1.1"
1586215853

15863-
schema-utils@^0.4.5:
15864-
version "0.4.7"
15865-
resolved "https://registry.yarnpkg.com/schema-utils/-/schema-utils-0.4.7.tgz#ba74f597d2be2ea880131746ee17d0a093c68187"
15866-
integrity sha512-v/iwU6wvwGK8HbU9yi3/nhGzP0yGSuhQMzL6ySiec1FSrZZDkhm4noOSWzrNFo/jEc+SJY6jRTwuwbSXJPDUnQ==
15867-
dependencies:
15868-
ajv "^6.1.0"
15869-
ajv-keywords "^3.1.0"
15870-
1587115854
schema-utils@^1.0.0:
1587215855
version "1.0.0"
1587315856
resolved "https://registry.yarnpkg.com/schema-utils/-/schema-utils-1.0.0.tgz#0b79a93204d7b600d4b2850d1f66c2a34951c770"
@@ -18147,13 +18130,13 @@ v8flags@~3.2.0:
1814718130
dependencies:
1814818131
homedir-polyfill "^1.0.1"
1814918132

18150-
val-loader@^1.1.1:
18151-
version "1.1.1"
18152-
resolved "https://registry.yarnpkg.com/val-loader/-/val-loader-1.1.1.tgz#32ba8ed5c3607504134977251db2966499e15ef7"
18153-
integrity sha512-JLqLXJWCVLXTxbUeHhLpWkgl3+X3U8Bl0vY7rTFZgFSbLJaEtAxuD2ixy/cM8w/gzC7sS3NE5IDSzClDt332sw==
18133+
val-loader@^2.1.2:
18134+
version "2.1.2"
18135+
resolved "https://registry.yarnpkg.com/val-loader/-/val-loader-2.1.2.tgz#3f2efaed5791791727df62858ccaa07fc27579e7"
18136+
integrity sha512-slp7F4QaEE3h2dCKb28ulCkgVYqpbTcx9u/8or+lpWGOn5v7+hrQXZ+dGbblrIf2LBkVZBCiinLh7DgYO4Ds5g==
1815418137
dependencies:
18155-
loader-utils "^1.0.0"
18156-
schema-utils "^0.4.5"
18138+
loader-utils "^2.0.0"
18139+
schema-utils "^3.0.0"
1815718140

1815818141
validate-npm-package-license@^3.0.1:
1815918142
version "3.0.4"

0 commit comments

Comments
 (0)